The Current Framework and the Purpose of the Law
Cybersecurity in Georgia is governed today by the law on information security — a separate cybersecurity law has not yet been adopted, and this law is the operating regime. Its purpose is to promote effective information security protection, establish the rights and duties of the public and private sectors, and define the mechanisms of state control. The framework covers critical information systems and their subjects and is the legal foundation of critical infrastructure protection obligations.
Key Concepts and Categories of Subjects
Article 2 defines the key concepts: information security protects the access, integrity, authentication, confidentiality and continuous operation of information and systems; a cyberattack uses an electronic device or network to violate the integrity of systems or obtain information unlawfully; a computer incident violates the confidentiality, integrity or availability of information. A critical information system is one whose continuous functioning is important for defense, economic security, state government or society. Subjects fall into three categories: the first — state and municipal bodies and state enterprises created with more than 50% state participation; the second — electronic communication companies; the third — private legal entities. The list is approved by the government on the proposal of the Ministry of Justice, agreed with the defense and interior ministries and the State Security Service.
The perimeter of the most stringent duties is not fixed inside the law itself: the categories of critical information system subjects are determined by decree of the Government of Georgia — the first category covers state and municipal bodies and state enterprises, the second electronic communications companies, and the third other private-law legal entities. Whether an organisation falls inside the regime is therefore checked against the current decree, not against the statute alone.
Scope, Exclusions and the Security Policy
Under Article 3, the law applies to the subject and to organizations connected with it through employment, internship or contract. In compiling the list, the severity of disruption, expected economic damage, the necessity of the service, the number of users and the subject’s finances are considered. The law does not apply to the media, publishers’ editorial offices, scientific, educational, religious and social organizations and political parties; any legal entity may voluntarily assume these obligations. A commercial bank that is not a subject follows National Bank rules. The law does not affect freedom of information and personal data norms.
Under Article 4, the subject must adopt internal-use rules defining its information security policy. The policy must satisfy the minimum requirements, established by taking into account the standards of the International Organization for Standardization, the US National Institute of Standards and Technology, and the Information Systems Audit and Control Association. The adopted rules are submitted for review: first- and second-category subjects — to the Operative-Technical Agency, the third — to the Digital Governance Agency, and the defense sector — to the Cybersecurity Bureau. All three bodies analyze the documents and issue binding instructions to cure defects.
The Incident Response System
Under Article 8, incident management in cyberspace is exercised by the computer incident response team of the Digital Governance Agency. Priority threats include a cyberattack threatening human life and health, state interests or the country’s defense capability, an attack on a subject’s systems, a threat to financial resources or property, and any other sufficiently serious action. Under Article 10, the subject identifies incidents using a network sensor and immediately notifies the relevant response team. The team examines the incident and issues binding instructions, to which the subject must respond within a reasonable period. In defense, incidents are managed by the Cybersecurity Bureau’s team, with access to the sensor and the subject’s assets; the response period for its instructions is at most 1 month. The teams create a unified information-sharing platform.
Liability for Violations
Article 10-8 establishes administrative sanctions: failure to notify the identification of a computer incident, failure to fulfill binding instructions, or failure to submit information on the measures taken entails, for a first-category subject, a warning or a fine of 5 000 GEL, and repetition of the same violation within 1 year — a fine of 10 000 GEL. The same sanctions apply to third-category subjects. The operator’s specific obligations — audits, appointment of a manager and a specialist, asset management — are established by other articles of the law and are discussed on a separate page.
Frequently Asked Questions
Which law regulates cybersecurity in Georgia?
The law on information security; a separate cybersecurity law has not yet been adopted, and the operating regime rests on this law.
Who are the three regulators?
For the first and second categories — the Operative-Technical Agency; for the third — the Digital Governance Agency; for the defense sector — the Cybersecurity Bureau.
Whom does the law not cover?
The media, publishers’ editorial offices, scientific, educational, religious and social organizations, and political parties.
What fine follows from concealing an incident?
A warning or a 5 000 GEL fine; in case of repetition — a 10 000 GEL fine.
How We Help on Legal.ge
On Legal.ge we help organizations determine their category and obligations, prepare the security policy and interact with the regulators. Contact our team on any issue of cybersecurity legislation.
